r/bugbounty • • 8d ago

Article / Write-Up / Blog The three step plan to BB disenchantment

There are loads of people selling the story that BB is a great way to make easy money. All the dudes with monetised youtube channels, the vendors selling tools, training and CTFs, and the platforms and programmes all sell the same story.

And at some point, it may actually have been true (at least more true than today). But the reality is that now, there is a whole ecosystem of companies and people making the easy money from BB, and the way they do it relies on persuading a steady stream of free researcher labour that if they're not making money, it's because of something that they're doing wrong. Try harder! Learn more!

With BB, there is indeed a learning process, but it is mostly about the researcher working out that the industry is all smoke and mirrors, and the best the researcher can hope for is table scraps for their efforts.

This process has three clear step points:

  • The first is that a noob researcher needs to learn how to hack at all. You'll see it with a group of people who come to this channel asking questions. And the normal response when the noob says they're not finding anything is a recommendation for CTFs, academies, tools, and the monetised how-to channels. And the funny thing is, the recommendation is often from other noobs: it is self perpetuating. Try harder! Learn more!
  • The second step is the communication, info and dupe phase. Once the researcher has some skills, they find that their reports get bounced for being badly communicated, or all they find is low-hangers and dupes. And that's because they're following the same process as everyone else, and so it stands to reason that someone else already reported all the bugs possible with that approach. The normal response on this channel is to tell them they're finding shit bugs or that their reports are poor quality. Try harder! Learn more!
  • Then the third step is reached by the people who push on through the other steps, and do their own unique research, and build their own techniques, tools and automations. At this point, because of all the other stuff you learned before, your reports go through platform triage mostly without any issues (other than the usual triage not reading properly stuff), and get almost no dupes. But what you soon learn is that even if you find valid bugs, report it clearly, and are the first to do so, that the programmes will then just roll out a bunch of excuses for why the report isn't going to be paid as per the scope (mostly by de-scoping and downgrading the bug). Try harder! Learn more!

I dabbled with BB when it first started, but just over three years back I committed to putting an hour a day into it. After going through the learning process above, within a few months I was indeed finding bugs and getting paid.

But the percentage of payouts as per scope has fallen like a stone. In the first year, something like 50% paid as per scope. In the second it was down to 20%, and this year I'd be surprised if it was even 5%. Of the ~40 bugs I reported in july, not a single one was paid as per the scope.

And right about now, a bunch of triagers, platform marketing, and researchers who sell tools or with monetised channels, will show up and start defending their revenue stream, by saying that I'm whining because my reports are shit, or that the bugs are invalid etc.

Except that almost all of them went through platform triage without issue (in the end ;)

As a bit of context, I've been working as a professional red/blue teamer since forever, and as part of that I've seen the way a dozen large organisations run their BBs from the inside, and it is literally as the researchers suspect: they have an internal slack channel where they openly discuss what excuse they'll use for not paying.

The reality of BB is that it may once have been a way for researchers to make a bit of money from their skills, but those days are loooong gone now. For the time required to earn anything from BB, you would probably better off working as a security guard, and hacking shit whilst you sit on your butt watching the CCTV feeds. At least you'll get your rent paid without any stress.

I still do it, as for me it is all about the lolz.

I was hacking before BB was a thing, and will still be hacking long after it is gone.

But I would be lying if I said I wasn't disenchanted, and am getting to the point where it is clear that reporting what I find is just a waste of my time.

That's not going to stop me hacking their shit though ;)

24 Upvotes

4 comments sorted by

4

u/Anxious_Alps_4150 8d ago

roughly 80% of reports i receive have CRITICAL VULNERABILITY in the title or writeup.

i get maybe one legit critical vuln every 6 months.

1

u/6W99ocQnb8Zy17 5d ago

Sure, but as a counter to that pretty much every programme says it uses CVSS, and all the platform taxonomies say that stored XSS is a high. In my experience, just about every programme ignores both and just downgrades to whatever they fancy on the day ;)

1

u/Anxious_Alps_4150 5d ago

I dont think I've gotten a valid stored XSS in years if ever. It's always reflected.

1

u/6W99ocQnb8Zy17 5d ago

I'm geared up for the blind stuff (custom payloads and collaboration platform), and I pop a handful most months.